Parsers¶
Package parsers for lockfiles across ecosystems (Python, Node.js, Go, Rust, Java, .NET, Ruby, Elixir/Erlang Hex, Dart/Flutter Pub, C/C++, and OS packages).
agent_bom.parsers ¶
Parse package dependencies from MCP server directories.
builtin_inventory_parser_registrations ¶
Return built-in package inventory parser registrations.
Source code in src/agent_bom/parsers/__init__.py
register_inventory_parser ¶
Register an inventory parser with capability metadata.
list_registered_inventory_parsers ¶
Return registered inventory parsers with capability declarations.
Source code in src/agent_bom/parsers/__init__.py
inventory_parser_registry_warnings ¶
Return sanitized non-fatal registry loading warnings.
registry_entry_for_references ¶
Return the one (key, entry) whose key or package equals a reference.
Identifiers compare exactly (PEP 503 for PyPI). Several matching entries make the attribution ambiguous, so nothing is returned.
Source code in src/agent_bom/parsers/__init__.py
detect_docker_image_package ¶
Extract the image reference from docker/podman MCP server commands.
Source code in src/agent_bom/parsers/__init__.py
lookup_mcp_registry ¶
Look up an MCP server's packages using the bundled registry.
Matches only on an exact package identifier in the command or args
(e.g. npx -y @modelcontextprotocol/server-filesystem); see
:func:_match_registry_entry.
Preserves the registry's latest_version in registry_version for drift comparison, and tries to detect the actual installed version from args. If no installed version is detectable, version is set to "latest" so the resolver can query npm/PyPI for the real current version.
Source code in src/agent_bom/parsers/__init__.py
get_registry_entry ¶
find_server_directory ¶
Attempt to find the MCP server's source directory.
Source code in src/agent_bom/parsers/__init__.py
extract_packages ¶
extract_packages(server: MCPServer, resolve_transitive: bool = False, max_depth: int = 3, smithery_token: str | None = None, mcp_registry: bool = False) -> list[Package]
Extract all packages for an MCP server.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
server
|
MCPServer
|
The MCP server to extract packages from |
required |
resolve_transitive
|
bool
|
If True, resolve transitive dependencies for npx/uvx packages |
False
|
max_depth
|
int
|
Maximum depth for transitive dependency resolution |
3
|
smithery_token
|
str | None
|
Optional Smithery API key for live registry fallback |
None
|
mcp_registry
|
bool
|
If True, query the Official MCP Registry as a fallback |
False
|
Source code in src/agent_bom/parsers/__init__.py
526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 | |
summarize_project_inventory ¶
Summarize manifest/lockfile coverage for a project scan.
This keeps lockfile-driven project scanning visible in CLI/JSON output so users can tell whether a project scan was backed by resolved lockfiles or only manifest declarations.
Source code in src/agent_bom/parsers/__init__.py
758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 | |
scan_project_directory ¶
scan_project_directory(root: Path, max_depth: int = 5, *, follow_symlinks: bool = False, warnings: list[str] | None = None) -> dict[Path, list[Package]]
Recursively walk root for package manifests and parse all packages.
Returns a mapping of {directory: [Package, ...]} for each directory
that contains at least one supported manifest file. Directories in
_SKIP_DIRS and hidden directories (starting with .) beyond the
root are silently skipped.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
root
|
Path
|
Project root directory to scan. |
required |
max_depth
|
int
|
Maximum directory depth to descend (default 5). |
5
|
follow_symlinks
|
bool
|
Whether to descend into symlinked directories. |
False
|
warnings
|
list[str] | None
|
Optional list populated with skipped or cross-boundary paths. |
None
|
Returns:
| Type | Description |
|---|---|
dict[Path, list[Package]]
|
Dict mapping each manifest-bearing directory to its parsed packages. |
dict[Path, list[Package]]
|
Empty dict if no manifests are found. |
Source code in src/agent_bom/parsers/__init__.py
853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 | |